Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Linguistic Lumberjack (CVE-2024-4323) is a critical vulnerability in the Fluent Bit logging utility that can allow DoS, information disclosure and possibly RCE.

CyberArk agreed to acquire machine identity management Venafi from Thoma Bravo for $1.54 billion.

CISA executive assistant director for cybersecurity Eric Goldstein is leaving the agency after more than three years.

Health insurance firm WebTPA says the personal information of 2.4 million individuals was compromised in a data breach.

Roundup of the cybersecurity-related merger and acquisition (M&A) deals announced in the first half of May 2024.

These strategies can help cybersecurity startups navigate the current market dynamics, focusing on modern buyer behavior, updated KPIs, brand awareness, and effective sales and marketing alignment.

MediSecure says data related to prescriptions distributed until November 2023 was compromised in a ransomware attack.

The American Radio Relay League (ARRL) has been targeted in a cyberattack that resulted in disruption and possibly a data breach.

Jan Leike, who ran OpenAI’s “Super Alignment” team, believes there should be more focus on preparing for the next generation of AI models, including on things like safety.

Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It’s opt-in by default.

Noteworthy stories that might have slipped under the radar: FBI is targeting Scattered Spider, Australia’s MediSecure hacked, new Wi-Fi attack.

People on the Move

CISA executive assistant director for cybersecurity Eric Goldstein is leaving the agency after more than three years.

OT zero trust access and control company Dispel has appointed Dean Macris as its CISO.

Cloud identity and security solutions firm Saviynt has hired former Gartner Analyst Henrique Teixeira as Senior Vice President of Strategy.

PR and marketing firm FleishmanHillard named Scott Radcliffe as the agency’s global director of cybersecurity.

Portnox, a provider of zero trust access control solutions, announced that Joseph Rodriguez has joined the company as Chief Revenue Officer.

More People On The Move
Slack data for AI Slack data for AI

Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It’s opt-in by default.

Microsoft Quick Assist Tool Abused for Ransomware Delivery

The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.

Palo Alto Networks partners with IBM on cybersecurity Palo Alto Networks partners with IBM on cybersecurity

Palo Alto Networks and IBM announced a significant partnership to jointly provide cybersecurity solutions.

Top Cybersecurity Headlines

Linguistic Lumberjack (CVE-2024-4323) is a critical vulnerability in the Fluent Bit logging utility that can allow DoS, information disclosure and possibly RCE.

CyberArk agreed to acquire machine identity management Venafi from Thoma Bravo for $1.54 billion.

CISA executive assistant director for cybersecurity Eric Goldstein is leaving the agency after more than three years.

Health insurance firm WebTPA says the personal information of 2.4 million individuals was compromised in a data breach.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 25-26, Ritz-Carlton, Half Moon Bay, CA]

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit dives into Threat hunting tools and frameworks, and explores the value of threat intelligence data in the defender’s security stack.

Learn More

Vulnerabilities

Cybercrime

A few days ago I got back from an AMTSO workshop in Munich. AMTSO is the Anti-Malware Testing Standards Organization, and I also wrote about it back in June. It’s essentially a coalition of organizations with an interest in improving anti-malware testing, and as you might expect, its current membership largely consists of security vendors and testers. Why would you expect that?

Science Applications International Corporation (SAIC) announced today that it has teamed with the University of Maryland (UMD) to support initiatives that promote education, research, and technology development in cybersecurity.

Webroot today announced it has acquired Prevx, a UK based provider of cloud-based anti-malware solutions.Prevx provides cloud-based antivirus protection and behavior-based malware detection, helping to block threats before they can reach a PC or corporate network.

The PCI Security Standards Council (PCI SSC), the industry standards body that oversees the Payment Card Industry Data Security Standard (PCI DSS), PIN Transaction Security (PTS) requirements and the Payment Application Data Security Standard (PA-DSS), this week released version 2.0 of the PCI DSS and PA-DSS.

F-Secure this week announced that that the newest version of its Messaging Security Gateway product now also offers 256 bit AES encryption for email, helping to protect sensitive data being shared between users and helping to comply with corporate security policies.

Symantec today released its October 2010 MessageLabs Intelligence Report, which showed that cybercriminals are increasingly launched targeted attacks.According to the report, targeted attacks have increased from one to two attacks per week in 2005 to 77 attacks per day in October 2010.

Privacy Breach Solution Targets Large and Complex Health Care ProvidersFairWarning, Inc., a company that provides solutions to monitor and protect Electronic Health Records, this week announced the availability of HP based high availability privacy breach solutions designed for very large and sophisticated care providers.Due to the escalating visibility and damages resulting from patient privacy breaches, breach detection is transitioning into a necessity for every care provider.

Juniper's Global Threat Center Will Focus Exclusively on Mobile ThreatsJuniper Networks this week announced the opening of the Juniper Global Threat Center in Columbus, Ohio to provide around-the-clock, global monitoring of mobile security threats to consumers and enterprises.

Study Shows Americans Support "Internet Kill Switch" - National Security Remains Top Concern for AmericansSixty-one percent of Americans said the President should have the ability to shut down portions of the Internet in the event of a coordinated malicious cyber attack, according to a recent study conducted by information technology giant, Unisys.

Report Reveals the Riskiest Web Domains to VisitWeb risk climbed to a record 6.2% of more than 27 million live domains evaluated for the 2010 Mapping the Mal Web report released today by McAfee. According to the report, the world’s most heavily trafficked web domain, .COM, is now the riskiest, with fifty-six percent of all risky sites discovered ending in .COM.

Smaller botnets are cheaper and easier to build out and operate, and criminals have already realized that large-scale botnets attract unwanted attention

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

A critical vulnerability tracked as CVE-2024-34359 and dubbed Llama Drama can allow hackers to target AI product developers.

Cloud Security

Cloud Security

Linguistic Lumberjack (CVE-2024-4323) is a critical vulnerability in the Fluent Bit logging utility that can allow DoS, information disclosure and possibly RCE.